CISM Certified Information Security Manager – Question0963

Which of the following represents a PRIMARY area of interest when conducting a penetration test?

A.
Data mining
B. Network mapping
C. Intrusion Detection System (IDS)
D. Customer data

Correct Answer: B

Explanation:

Explanation:
Network mapping is the process of determining the topology of the network one wishes to penetrate. This is one of the first steps toward determining points of attack in a network. Data mining is associated with ad hoc reporting and. together with customer data, they are potential targets after the network is penetrated. The intrusion detection mechanism in place is not an area of focus because one of the objectives is to determine how effectively it protects the network or how easy it is to circumvent.